Cloud de Confiance 與 Google Cloud 的 Secret Manager 差異

Secret Manager 是安全又便利的儲存系統,可以儲存 API 金鑰、密碼、憑證和其他機密資料。本頁說明 Cloud de Confiance 與 Google Cloud 版本的 Secret Manager 有哪些差異。

如要進一步瞭解 Secret Manager,請參閱「Secret Manager 總覽」和其餘 Secret Manager 說明文件。

主要差異

Cloud de Confiance 版本的 Secret Manager 與 Google Cloud 版本有些許差異,主要包括:

  • Google Kubernetes Engine 的 Secret Manager 外掛程式無法使用。
  • 無法為密鑰啟用使用者自管複製功能。
  • 目前僅提供 Secret Manager API 第 1 版。
  • 區域端點無法使用。
  • 導覽文件端點要求需要 API 金鑰。

本節後續部分會說明更多差異細節。如果您已熟悉 Google Cloud,建議先仔細瞭解這些差異;若打算設計在 Cloud de Confiance上執行的應用程式,更有必要這麼做。此外,也建議一併參閱「 Cloud de Confiance 與 Google Cloud 的一般差異」。

如要使用目前無法在 Cloud de Confiance中使用的特定 Secret Manager 功能,請與Cloud de Confiance 支援團隊聯絡。 如要在 Cloud de Confiance推出新功能時接收通知,請訂閱版本資訊。除非另有規定,否則預覽版功能不適用於 Cloud de Confiance。

可用性和災難復原

密碼複寫

無法使用採用使用者自管複製政策的密鑰。如要建立密鑰,但不想指定儲存區域,請使用自動複製功能。如要符合資料落地規定,請建立區域性密鑰。

工作流程和工具

API 版本

目前僅提供 Secret Manager API 第 1 版。v1beta1 和 v1beta2 API 版本已無法使用。

導覽文件端點

在 Cloud de Confiance中,無法使用身分存取權杖存取 Secret Manager REST 導覽文件端點 (/$discovery/rest)。

如要存取導覽文件端點,請使用以查詢參數形式傳遞的 API 金鑰:

https://secretmanager.s3nsapis.fr/$discovery/rest?version=v1&key=API_KEY

如要瞭解如何建立 API 金鑰,請參閱「使用 API 金鑰」一文。為確保安全,建議套用 API 金鑰限制,只允許呼叫 Secret Manager API。

網路

區域端點

無法使用區域端點。 Cloud de Confiance 自動將流量導向適當的區域堆疊,而不使用區域端點。

存取區域密鑰的網址格式在 Google Cloud 和 Cloud de Confiance universe 之間有所不同。

Google Cloud:

https://secretmanager.REGION.rep.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/secrets?secret_id=SECRET_ID

Cloud de Confiance:

https://secretmanager.s3nsapis.fr/v1/projects/PROJECT_ID/locations/REGION/secrets?secret_id=SECRET_ID

下列資訊也可能影響您在 Cloud de Confiance by S3NS使用及設計 Secret Manager 的方式。這些指南涵蓋在 Cloud de Confiance作業的一般資訊,包括說明文件、安全和存取控管、計費、工具和服務使用情形。

如要進一步瞭解 Cloud de Confiance 中的其他服務和功能,以及與 Google Cloud 相似服務的差異,請參閱產品清單。